We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).
Reserved 2025-05-19 | Published 2025-05-21 | Updated 2025-05-23 | Assigner redhat2025-05-20: | Reported to Red Hat. |
2025-05-20: | Made public. |
access.redhat.com/security/cve/CVE-2025-4969
bugzilla.redhat.com/show_bug.cgi?id=2367552 (RHBZ#2367552)
Support options